There were not too much communication about client side, but the OpenSSL HeartBleed bug can be exploited at client side too: a malicious website can reach all memory of the browser (including all previously used unencrypted passwords). Google say, some version of android 4.1.1 affected -...